CVE-2026-82477
5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Summary
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MITRE | Heimdall | 2.11.6 < 2.14.0 | affected |
Weaknesses
- CWE-918: CWE-918 Server-Side Request Forgery (SSRF)
References
- https://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpch
- https://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b485937b
- https://github.com/mitre/heimdall2/releases/tag/v2.14.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.